Trellix · Capability
Trellix EDR API — Threats
Trellix EDR API — Threats. 2 operations. Lead operation: List detected threats. Self-contained Naftiko capability covering one Trellix business surface.
What You Can Do
GET
Listthreats
— List detected threats
/v1/edr/v2/threats
GET
Getthreat
— Get threat details
/v1/edr/v2/threats/{threatid}
MCP Tools
list-detected-threats
List detected threats
read-only
idempotent
get-threat-details
Get threat details
read-only
idempotent